<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #IAM</title><description>Cybersecurity articles tagged #IAM on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Hundreds of Leaked AWS Keys Expose Corporate Cloud Accounts</title><link>https://runtimerebel.com/blog/hundreds-of-leaked-aws-keys-expose-corporate-cloud-accounts</link><guid isPermaLink="true">https://runtimerebel.com/blog/hundreds-of-leaked-aws-keys-expose-corporate-cloud-accounts</guid><description>Research reveals over 9,000 publicly exposed Amazon Web Services access keys remain active, including hundreds of root and administrator credentials.</description><pubDate>Fri, 21 Aug 2026 16:21:53 GMT</pubDate><category>AWS</category><category>Credential Theft</category><category>Cloud Security</category><category>IAM</category><category>Data Breach</category></item><item><title>SSRF Scans Target Cloud Metadata Service for Credential Access</title><link>https://runtimerebel.com/blog/ssrf-scans-target-cloud-metadata-service-for-credential-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/ssrf-scans-target-cloud-metadata-service-for-credential-access</guid><description>Attackers are conducting widespread scans for Server-Side Request Forgery (SSRF) vulnerabilities to access cloud metadata services and retrieve sensitive IAM credentials.</description><pubDate>Wed, 19 Aug 2026 16:24:58 GMT</pubDate><category>SSRF</category><category>Cloud Security</category><category>IAM</category><category>Credential Theft</category><category>Metadata Service</category></item><item><title>Synthetic Identity Fraud: Securing Non-Human Identities (NHI)</title><link>https://runtimerebel.com/blog/synthetic-identity-fraud-securing-non-human-identities-nhi</link><guid isPermaLink="true">https://runtimerebel.com/blog/synthetic-identity-fraud-securing-non-human-identities-nhi</guid><description>Attackers are leveraging synthetic identity fraud to compromise machine identities. Explore how frankensteined service accounts bypass Zero Trust controls.</description><pubDate>Thu, 23 Jul 2026 14:04:39 GMT</pubDate><category>Machine Identity</category><category>Synthetic Identity Fraud</category><category>IAM</category><category>Non Human Identities</category><category>Cloud Security</category></item><item><title>Exposed Cloud Functions: Hardening GCP Serverless Against LFI &amp; RCE</title><link>https://runtimerebel.com/blog/exposed-cloud-functions-hardening-gcp-serverless-against-lfi-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/exposed-cloud-functions-hardening-gcp-serverless-against-lfi-rce</guid><description>Mandiant identifies exposed serverless functions as initial access points. Learn to harden Google Cloud Run against LFI and RCE with IAM, WAF, and secure SDLC.</description><pubDate>Wed, 15 Jul 2026 17:23:18 GMT</pubDate><category>Google Cloud</category><category>Cloud Run</category><category>Serverless</category><category>LFI</category><category>Command Injection</category><category>RCE</category><category>WAF</category><category>Cloud Armor</category><category>IAM</category><category>Mandiant</category><category>Cloud Security Posture Management</category></item><item><title>Opal Security Series B: Scaling AI-Native Identity Governance</title><link>https://runtimerebel.com/blog/opal-security-series-b-scaling-ai-native-identity-governance</link><guid isPermaLink="true">https://runtimerebel.com/blog/opal-security-series-b-scaling-ai-native-identity-governance</guid><description>Opal Security secures $23 million in Series B funding to scale its AI-native identity governance platform for hybrid and multi-cloud environments.</description><pubDate>Sat, 06 Jun 2026 12:35:13 GMT</pubDate><category>Opal Security</category><category>Identity Governance</category><category>IAM</category><category>Cloud Security</category><category>IGA</category></item><item><title>Shrinking IAM Attack Surface via Identity Visibility Platforms (IVIP)</title><link>https://runtimerebel.com/blog/shrinking-iam-attack-surface-via-identity-visibility-platforms-ivip</link><guid isPermaLink="true">https://runtimerebel.com/blog/shrinking-iam-attack-surface-via-identity-visibility-platforms-ivip</guid><description>Enterprise security teams must tackle Identity Dark Matter using IVIP to eliminate blind spots in fragmented identity and access management environments.</description><pubDate>Wed, 03 Jun 2026 13:47:34 GMT</pubDate><category>IAM</category><category>IVIP</category><category>Identity Security</category><category>Access Management</category><category>Identity Dark Matter</category></item><item><title>AI Agent Identity Security: Budget Dynamics &amp; Governance Priorities</title><link>https://runtimerebel.com/blog/ai-agent-identity-security-budget-dynamics-governance-priorities</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agent-identity-security-budget-dynamics-governance-priorities</guid><description>New Omdia research reveals AI agent proliferation is fundamentally altering enterprise identity security budget dynamics, demanding distinct governance and management…</description><pubDate>Thu, 21 May 2026 20:41:56 GMT</pubDate><category>AI Agents</category><category>Identity Security</category><category>IAM</category><category>Governance</category><category>Budget Dynamics</category><category>Omdia</category></item><item><title>Securing Identity Attack Paths: Protecting Cached AWS Credentials</title><link>https://runtimerebel.com/blog/securing-identity-attack-paths-protecting-cached-aws-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-identity-attack-paths-protecting-cached-aws-credentials</guid><description>Attackers exploit cached AWS access keys to achieve lateral movement. Learn how identity-based attack paths expose 98% of cloud entities and how to defend.</description><pubDate>Thu, 21 May 2026 13:17:05 GMT</pubDate><category>AWS</category><category>Identity Security</category><category>Cloud Security</category><category>Lateral Movement</category><category>IAM</category></item><item><title>Oracle Red Bull Racing: Securing F1 IP via Identity Automation</title><link>https://runtimerebel.com/blog/oracle-red-bull-racing-securing-f1-ip-via-identity-automation</link><guid isPermaLink="true">https://runtimerebel.com/blog/oracle-red-bull-racing-securing-f1-ip-via-identity-automation</guid><description>Discover how Oracle Red Bull Racing leverages identity governance automation to protect intellectual property and streamline security in high-stakes F1 environments.</description><pubDate>Thu, 30 Apr 2026 16:40:00 GMT</pubDate><category>Oracle Red Bull Racing</category><category>Identity Governance</category><category>IAM</category><category>SailPoint</category><category>F1 Security</category></item><item><title>Secure AI Agent Delegation: Bridging the Authority Gap</title><link>https://runtimerebel.com/blog/secure-ai-agent-delegation-bridging-the-authority-gap</link><guid isPermaLink="true">https://runtimerebel.com/blog/secure-ai-agent-delegation-bridging-the-authority-gap</guid><description>AI agents introduce a structural authority gap in enterprise security. Learn how continuous observability serves as a decision engine for delegation.</description><pubDate>Fri, 24 Apr 2026 12:31:24 GMT</pubDate><category>AI Security</category><category>Governance</category><category>IAM</category><category>LLM Security</category><category>Observability</category></item><item><title>Reducing IAM Attack Surface with Identity Visibility Platforms</title><link>https://runtimerebel.com/blog/reducing-iam-attack-surface-with-identity-visibility-platforms</link><guid isPermaLink="true">https://runtimerebel.com/blog/reducing-iam-attack-surface-with-identity-visibility-platforms</guid><description>Learn how Identity Visibility and Intelligence Platforms (IVIP) eliminate Identity Dark Matter and reduce risk across fragmented enterprise environments.</description><pubDate>Wed, 08 Apr 2026 12:26:32 GMT</pubDate><category>IAM</category><category>IVIP</category><category>Identity Dark Matter</category><category>Attack Surface Management</category><category>Machine Identity</category></item><item><title>Securing Autonomous AI Agents: Identity and Access Management</title><link>https://runtimerebel.com/blog/securing-autonomous-ai-agents-identity-and-access-management</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-autonomous-ai-agents-identity-and-access-management</guid><description>Enterprises must address the security risks of autonomous AI agents by treating them as non-human identities with granular access controls and monitoring.</description><pubDate>Tue, 17 Mar 2026 16:30:06 GMT</pubDate><category>AI Security</category><category>IAM</category><category>Non Human Identities</category><category>AI Agents</category><category>CISO Strategy</category></item><item><title>AWS Honeytoken Implementation: Proactive Detection of IAM Credential Theft</title><link>https://runtimerebel.com/blog/aws-honeytoken-implementation-proactive-detection-of-iam-credential-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/aws-honeytoken-implementation-proactive-detection-of-iam-credential-theft</guid><description>Learn how to implement AWS honeytokens using IAM and CloudTrail to detect unauthorized credential usage and mitigate lateral movement in cloud environments.</description><pubDate>Mon, 09 Mar 2026 04:41:00 GMT</pubDate><category>AWS</category><category>Honeytokens</category><category>IAM</category><category>CloudTrail</category><category>Detection Engineering</category></item><item><title>SLH Recruits Women for $1,000 IT Help Desk Vishing Attacks</title><link>https://runtimerebel.com/blog/slh-recruits-women-for-1000-it-help-desk-vishing-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/slh-recruits-women-for-1000-it-help-desk-vishing-attacks</guid><description>Scattered LAPSUS$ Hunters (SLH) are offering financial incentives to recruit women for vishing campaigns targeting corporate IT help desks and IAM systems.</description><pubDate>Wed, 25 Feb 2026 16:30:53 GMT</pubDate><category>Scattered LAPSUS Hunters</category><category>Vishing</category><category>Social Engineering</category><category>IT Help Desk</category><category>IAM</category></item><item><title>Mitigating Identity Risks in Autonomous AI Agent Workflows</title><link>https://runtimerebel.com/blog/mitigating-identity-risks-in-autonomous-ai-agent-workflows</link><guid isPermaLink="true">https://runtimerebel.com/blog/mitigating-identity-risks-in-autonomous-ai-agent-workflows</guid><description>Enterprise security must evolve to manage AI agents as non-human identities (NHIs) by implementing intent-based controls and solving over-scoped privilege risks.</description><pubDate>Tue, 24 Feb 2026 16:28:36 GMT</pubDate><category>AI Security</category><category>NHI</category><category>Non Human Identity</category><category>IAM</category><category>Governance</category><category>Machine Identity</category></item><item><title>Identity Prioritization: Shifting from Backlogs to Risk Math</title><link>https://runtimerebel.com/blog/identity-prioritization-shifting-from-backlogs-to-risk-math</link><guid isPermaLink="true">https://runtimerebel.com/blog/identity-prioritization-shifting-from-backlogs-to-risk-math</guid><description>Enterprise identity programs must evolve from ticket-based prioritization to dynamic risk math models to manage the surge of human and non-human identities.</description><pubDate>Tue, 24 Feb 2026 12:20:29 GMT</pubDate><category>IAM</category><category>Identity Security</category><category>Risk Management</category><category>Non Human Identities</category><category>Identity Threat Detection and Response</category></item></channel></rss>